Thanks for the replies. I checked ipconfig and the dns servers don't match the ip's. Now that I look at it the source address is different each time in the log. I would really like to use a sniffer to find out more but it's not allowed in the acceptable use policy. They probably wouldn't notice but I can't take any chances when graduating in Dec. I don't think it is a virus but could be. Our university decided to have students ditch their current AV for the one the school provided (McAfee Enterprise) this fall semester which I think they can remotely update them. Any idea on why the source IP would constantly change?